AUTHENTICATOR · CODE VAULT

Your data. Your control.

Privacy policy

Your authenticator vault stays on your device. We do not receive its keys, PIN or backup password.

Authenticator - Code Vault · Updated September 13, 2026

Who provides the app

Authenticator - Code Vault is provided by NEXORAONLINE ECOM - FZCO, United Arab Emirates. Contact us at hello@vilin-authenticator.com about this policy or your information. This policy covers the app and explains how contacting us or visiting this website differs from using the local vault.

Information on your device

The app stores authenticator secrets, account labels and vault state in an encrypted, device-only Keychain record. Your six-digit app PIN derives the encryption key; the PIN itself is not stored. If you enable Face ID or Touch ID, a biometric-protected Keychain item allows you to unlock the app. Code Vault does not receive or store your face or fingerprint data. Some preferences, such as whether biometric unlock is enabled, are stored locally.

Time-based verification codes are generated on your device. The app has no email registration, publisher-operated cloud synchronization, analytics SDK or advertising SDK. It does not send authenticator secrets, account labels, generated codes, PINs or backup passwords to us.

Camera, photos and clipboard

Camera access is used to read setup QR codes. You can instead select an image through the system photo picker or enter a setup key manually. Selected images are processed locally and are not saved or uploaded by the app. Images you originally saved in Photos remain there until you delete them.

Copying a verification code places it on the local device clipboard with an expiration of up to 30 seconds. Another app may access it during that time. The app covers sensitive views when backgrounded and during detected recording or mirroring; it does not prevent ordinary iOS screenshots.

Encrypted backups you choose to save

You can export a password-protected encrypted backup to a location you choose in Files. If you choose a cloud storage provider, that provider handles the file under your account and its own privacy terms. Code Vault does not operate that storage or receive the exported file or password. Compatible backups are decrypted locally when you import them. Exported copies remain outside the app until you delete them.

Keep your backup password and your account providers’ recovery codes somewhere safe. We cannot recover your vault, PIN, backup password or authenticator secrets.

Purchases and Apple services

Apple handles subscription payments and purchase records. The app uses StoreKit to obtain product information and verify subscription access. We do not receive your payment-card details. Apple may provide the publisher with sales, subscription and other reports through its developer services under Apple’s policies. These are distinct from the local vault contents. Apple’s own privacy practices apply to its services.

Website visits and support email

Opening this website sends ordinary web requests to the hosting infrastructure. The hosting provider may process technical information such as IP address, request time, requested page and browser details to deliver and secure the site. We do not add analytics scripts, advertising scripts or embedded third-party media to these pages. The hosting infrastructure may set security cookies and run checks to protect the website from automated abuse.

If you email us, we receive your email address and whatever you include in your message. Our email provider processes that correspondence so we can respond. We use support correspondence to answer requests and investigate issues, and retain it only as needed for support, security, legal obligations or resolving disputes. Please do not send setup keys, QR secrets, verification codes, PINs, backup files or passwords. You can ask us to delete support correspondence, subject to information we must retain.

Deletion, device passcode and recovery

Delete individual accounts in the app, or use Settings → Delete all vault data to remove the vault. Uninstalling the app may leave Keychain records on the same device; erase the vault first if you want to remove it. Deletion does not cancel an Apple subscription and does not remove backups you exported.

Removing your iPhone’s device passcode permanently erases the protected vault record. Save an encrypted backup before removing that passcode. Device-only Keychain data does not automatically transfer to a new phone. A compatible backup and its password, or recovery through each account provider, are your recovery options.

Your questions and choices

You control camera and biometric permissions through iOS, and can choose manual setup and PIN unlock. We cannot access, correct or delete your local vault remotely. For access, correction or deletion requests concerning information you sent us, contact hello@vilin-authenticator.com. Rights and retention requirements may depend on your location. We will update this page when our practices change and show the revised date above.